Obfuscation and .NET.

Richard Wiener · The Journal of Object Technology · 2005

Assemblies generated under .NET may be decompiled into easily recognized source code that is either identical or similar to the original source code.Individuals or companies deploying .NET generated assemblies that are targeted for client machines may unwittingly be distributing their source code -in most cases an unintended consequence.Since source code is generally considered a valuable intellectual asset, measures should be taken to prevent decompilation into easily recognized source code.Obfuscator software is aimed at making decompilation into easily recognized source code very difficult.This article examines the issue of obfuscation under .NET and reviews two obfuscator products.The test suite used to evaluate the two obfuscator products are applications taken from the forthcoming book by Richard Wiener entitled Modern Software Development Using C#/.NET (to be published by Course Technology in late 2005). The Nature of .NET AssembliesAssemblies in .NET consist of two major components: metadata and intermediate language code.The reflection capabilities of .NET languages and the metadata features of an assembly that include its classes and associated method signatures, fields, properties and events make it possible to reverse engineer and retrieve this intellectual property.The intermediate language code provides information regarding the details of each method implementation.This enables well constructed decompilers to reveal the details of proprietary algorithms that you would typically not want users to have access to.To illustrate this, consider the following class, in Listing 1, designed to perform generic sorting using the simple and relatively inefficient selection-sort algorithm.

Read the paper · More papers on PaperTik